How to fix multiple GitHub issues at once using the Jules extension for Gemini CLI

Google Cloud TechAbout 6 min readOct 29, 2025Watch original
THE SUMMARYAI-generated

Key Concepts

  • Gemini CLI: A command-line interface tool that integrates with Gemini models.
  • Jules Extension: A specific extension for Gemini CLI, likely designed for automating tasks.
  • GitHub Personal Access Token: A token used to authenticate with GitHub, granting specific permissions.
  • Prompt Injection Vulnerabilities: Security flaws where malicious input can manipulate an AI model's behavior.
  • Cross-Site Scripting (XSS) Risks: Security vulnerabilities that allow attackers to inject malicious scripts into web pages viewed by other users.
  • Output Validation: The process of checking the output of a system to ensure it meets certain criteria and is safe.
  • Package Versions: Specific versions of software libraries or dependencies used in a project.
  • Input Length: The maximum or expected length of data provided as input to a system.
  • System Prompt: Instructions given to an AI model to guide its behavior and responses.
  • Self-Correction Layer: A mechanism within an AI system that allows it to review and correct its own output.
  • Pull Request (PR): A mechanism in version control systems (like Git) for proposing changes to a codebase.

Security Task Automation with Gemini CLI and Jules Extension

This video demonstrates the use of the Gemini CLI, specifically the Jules extension, to automate security-related tasks for an AI student assistant project. The process involves identifying, prioritizing, and resolving issues directly from the local development environment.

1. Issue Identification and Prioritization

  • Initial Setup: The user has a GitHub personal access token with "fine brain" permissions (likely meaning broad read access) stored in a .dm file named github_token. This token is used to interact with the GitHub repository.
  • Listing and Summarizing Issues: The user instructs Gemini CLI to list all issues in the repository and then summarize them, including details beyond just the titles, and rank them by severity.
    • Command Example: "Please use the GUP API and my personal access token in the DM file named get up token. List my issues in this repo. As a reminder, don't print my token out in the locks."
    • Result: Six issues were identified.
  • Prioritized Issue List:
    1. Prompt Injection Vulnerabilities: Two issues reported. (Most critical)
    2. Cross-Site Scripting (XSS) Risk: One issue.
    3. Suggestion for Output Validation: One suggestion.
    4. Adding Missing Package Versions in requirements.txt: One issue.
    5. Question about Input Length: One question.
  • Confirmation of Ranking: The user agrees with the ranking, indicating a clear prioritization strategy.

2. Automated Issue Resolution with Jules

Jules is tasked with addressing the identified issues, starting with the most critical ones.

  • Task 1: Addressing Prompt Injection Vulnerabilities
    • Objective: Update the system prompt in main.py to prevent the model from ignoring safety rules, revealing sensitive information (like student grades), or generating harmful content.
    • Action: The user instructs Jules to work on this. Jules confirms it has started and provides a URL (presumably for the task or a related log).
  • Task 2: Addressing Cross-Site Scripting (XSS) Risks
    • Objective: Audit the code for XSS risks and update it accordingly.
    • Action: The user asks Jules to "Please audit my code for any cross-size scripting risks and update my code accordingly." Jules confirms this session has also started.
  • Task 3: Implementing Output Validation (Self-Correction Layer)
    • Objective: Implement a "self-correction layer" where the model validates its own content for harmful material before sending it to the user.
    • Action: The user passes the suggestion directly to Jules: "Add selfcorrection layer. The model validates his own content for harmful content before sending it to user." This session also begins.

3. Monitoring and Publishing Changes

  • Jules's Console: The user checks Jules's console and sees three recent sessions initiated, corresponding to the three tasks assigned.
  • Reviewing Diffs and Publishing PRs: The user opens the first session, reviews the proposed code changes (the "diff"), and if satisfactory, clicks "Publish PR." This process is repeated for each completed task.
  • Status Check: The user asks Jules to list the tasks for the day to check their statuses. All tasks are reported as completed.

4. GitHub Pull Request Submission

  • Manual Submission: The user then navigates to GitHub to open the Pull Requests (PRs) that Jules has prepared.
  • Impact: With these three PRs, the user states that four issues (implying some issues might have been bundled or addressed by a single PR) are being addressed in the repository, ranging from critical to high importance.

5. Key Arguments and Perspectives

  • Efficiency of Automation: The core argument is that AI tools like Gemini CLI and Jules can significantly streamline the development workflow, especially for repetitive or time-consuming tasks like security patching.
  • Maintainer's Role: The maintainer's role shifts from manual coding to oversight, review, and strategic direction, allowing them to "step away while Jules worked in the background."
  • Security as a Priority: The video emphasizes addressing security vulnerabilities (prompt injection, XSS) as critical tasks, demonstrating how AI can be leveraged to improve code security.

6. Technical Terms and Concepts Explained

  • Gemini CLI Jules Extension: A tool that extends Gemini CLI's capabilities, likely for task automation and code interaction.
  • Prompt Injection: A security vulnerability where an attacker manipulates an AI's input to make it perform unintended actions or reveal sensitive data.
  • Cross-Site Scripting (XSS): A web security vulnerability that allows attackers to inject client-side scripts into web pages viewed by other users.
  • System Prompt: The foundational instructions given to an AI model that define its persona, rules, and objectives.
  • Self-Correction Layer: A feature where an AI model is designed to review and correct its own outputs for errors or harmful content before presenting them.
  • Pull Request (PR): A method for proposing changes to a codebase in a collaborative development environment.

7. Logical Connections

The video follows a logical progression:

  1. Problem Identification: New issues arise overnight.
  2. Assessment and Prioritization: Gemini CLI is used to list, summarize, and rank these issues.
  3. Automated Solution Generation: Jules extension is employed to tackle the prioritized issues.
  4. Verification and Integration: The user reviews Jules's proposed changes and submits them as Pull Requests on GitHub. This demonstrates a complete workflow from issue detection to code integration, powered by AI tools.

8. Data and Statistics

  • Number of Issues: Six issues were identified.
  • Number of PRs: Three Pull Requests were created.
  • Issues Addressed: Four issues were addressed across the three PRs.

9. Conclusion/Synthesis

The video effectively showcases how Gemini CLI, coupled with the Jules extension, can empower developers to automate critical security tasks. By leveraging AI for issue summarization, prioritization, code auditing, and even PR generation, maintainers can significantly improve their efficiency and the security posture of their projects. The ability to delegate these tasks and review them asynchronously highlights a powerful shift in software development workflows.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.